memos vulnerability allows arbitrarily modification or deletion registered identity providers in github.com/usememos/memos
memos vulnerability allows arbitrarily modification or deletion registered identity providers in github.com/usememos/memos
02 / AFFECTED SOFTWARE
Affected packages
2 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Service (DoS).
memos vulnerability allows arbitrarily modification or deletion registered identity providers in github.com/usememos/memos
Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Service (DoS).
05 / REFERENCES
Further evidence
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/65xxx/CVE-2025-65797.json
- https://github.com/usememos/memos/pull/5217
- https://herolab.usd.de/security-advisories/usd-2025-0057/
- https://nvd.nist.gov/vuln/detail/CVE-2025-65797
- http://memos.com
- http://usememos.com
- https://github.com/advisories/GHSA-99m2-qwx6-2w6f
- https://github.com/usememos/memos/commit/769dcd0cf9be83d472829f6e7903b201e42f6b3c
- https://herolab.usd.de/security-advisories/usd-2025-0057
- https://github.com/usememos/memos